CVE-2019-11201

UnknownEPSS 2.24%

Last modified

CVE-2019-11201 is a vulnerability of currently unknown severity. Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. EPSS estimates a 2.24% chance of exploitation in the next 30 days.

Description

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

Metrics

EPSS Probability
2.24%

80.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
DolibarrDolibarr Erp\/Crm9.0.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-11201?
Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.
How severe is CVE-2019-11201?
Severity scoring for CVE-2019-11201 is pending analysis. The EPSS model estimates a 2.24% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11201?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-11201?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST